Repository navigation
68 lines (63 loc) · 1.92 KB
/
Copy pathsecurity.yml
File metadata and controls
68 lines (63 loc) · 1.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
name: security
on:
push:
branches: [master, main]
pull_request:
branches: [master, main]
jobs:
supply-chain:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Install audit tools
run: |
python -m pip install --upgrade pip
pip install pip-audit
- name: pip-audit (transitive deps of any pip-installed tooling)
run: |
# keelwright is stdlib-only at runtime; this scans any tooling the repo pins.
pip-audit --require-hashes || true
- name: OSV-Scanner
uses: actions/osv-scanner-action@v1
with:
scan-args: |-
--recursive
./
continue-on-error: true
license-check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Verify MIT-0 license consistency
run: |
grep -q "MIT No Attribution" LICENSE || (echo "LICENSE must be MIT-0" && exit 1)
test -f NOTICE-MIT || (echo "NOTICE-MIT missing" && exit 1)
echo "license check OK"
secrets-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: R1/R2 security scan
run: |
pip install gitleaks semgrep
gitleaks protect --staged --redact -v
PYTHONPATH= semgrep scan --config=auto --error .
build-check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Verify skill index is up to date
run: |
python scripts/build_skill.py --check
- name: Assert SKILL.md index line count
run: |
test "$(wc -l < SKILL.md)" -le 250 || (echo "SKILL.md index exceeds 250 lines" && exit 1)